The Serial Interface Exploit
Google Chrome supports a highly advanced API known as Web Serial. This API allows websites to bypass the operating system’s standard networking stack and communicate directly with legacy serial ports (RS-232) and USB-to-serial adapters plugged into your computer. While useful for specialized web apps that flash firmware to networking routers or Arduino microcontrollers, it is a massive hardware vulnerability. Malicious websites can exploit this direct serial bridge to silently probe your attached hardware or execute raw commands against industrial equipment. To lock down your serial interfaces, you must paralyze this API.
How to Block Serial Port Access Globally
You can permanently sever the browser’s ability to see your serial hardware via Chrome’s Site Settings.
- Open the Google Chrome desktop browser.
- Click the three vertical dots (⋮) in the top right corner and select Settings.
- In the left-hand sidebar, click on Privacy and security.
- In the main window, click on Site settings.
- Scroll down to the “Permissions” heading and click to expand Additional permissions.
- Click on Serial ports.
- Under the “Default behavior” heading, select the radio button for “Don’t allow sites to connect to serial ports.”
Hardware Isolation
The change takes effect instantly. Google Chrome will completely sever its internal connection to your operating system’s serial communication drivers. The browser is now permanently blind to any physical COM ports or USB serial adapters attached to your machine. If a website attempts to execute a Web Serial script to scan your ports or open a connection, the API call will instantly auto-reject in the background, returning a null value. This guarantees absolute physical isolation between the web and your attached hardware.